A WhatsApp phishing campaign known as the “ballerina scam” is again circulating through messages sent from compromised contacts, tricking victims into visiting fake voting sites and authorizing access to their accounts. The attackers use the verification code to link their own device to the victim’s WhatsApp account, enabling session hijacking, message monitoring, and further spread to new targets. #WhatsApp #CERTAGID
Keypoints
- A phishing campaign on WhatsApp is abusing a fake “ballerina contest” or scholarship vote to lure victims.
- The message often comes from a known contact whose account was previously compromised, increasing trust.
- The fraudulent website mimics a real voting portal and presents finalists with photos, vote counts, and dance school details in Prague.
- The requested code is not for voting, but for authorizing a device controlled by attackers to link to the victim’s WhatsApp account.
- Once linked, the attacker can read chats and use the compromised account to send the same scam to the victim’s contacts.
- The campaign relies on trust chains within contact lists and can remain hidden because the victim’s phone continues working normally.
- CERT-AGID recommends checking linked devices, removing unknown sessions, and enabling two-step verification.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link – Victims receive a deceptive WhatsApp message containing a link to a fake voting site that lures them into the scam (‘il messaggio… invita a votare una giovane ballerina… Il collegamento conduce a un sito realizzato per apparire come un vero portale di votazione’).
- [T1589.003 ] Gather Victim Identity Information: Phone Numbers – The campaign relies on WhatsApp account recovery/verification flows where the attacker seeks a phone-based verification code tied to the victim’s account (‘non inserire numeri di telefono o codici di verifica su siti raggiunti tramite messaggi WhatsApp’).
- [T1098 ] Account Manipulation – Device Registration – The code is used to authorize an attacker-controlled device to be associated with the victim’s WhatsApp account (‘viene utilizzato per autorizzare il collegamento di un dispositivo controllato dagli attaccanti all’account della vittima’).
- [T1528 ] Steal Application Access Token / Session Hijacking – By linking their device, attackers maintain access to the account and abuse the active session without immediately disrupting the victim (‘un dispositivo non autorizzato rimane associato all’account, rendendo la compromissione meno evidente’).
- [T1213 ] Data from Information Repositories – After access is established, attackers can read the victim’s conversations stored within WhatsApp chats (‘L’account può quindi essere sfruttato per leggere le conversazioni’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – The scam is delivered through a web portal that imitates a legitimate voting website and guides users through the flow online (‘un sito realizzato per apparire come un vero portale di votazione’).
- [T1105 ] Ingress Tool Transfer – The campaign uses a remote web link as the delivery mechanism for the fraudulent voting page and verification flow (‘Il collegamento conduce a un sito…’).
Indicators of Compromise
- [URLs] Fake voting/verification site used in the scam – the article mentions a malicious link and a downloadable IoC list, but does not expose the actual URL here (‘Link: Download IoC’).
- [Account/session artifacts] Unauthorized WhatsApp linked device/session – attacker-controlled device linked to the victim account; users are told to check WhatsApp → Settings → Linked Devices (‘Dispositivi collegati’, ‘sessioni non riconosciute’).
- [Social engineering content] Scam lure messages – WhatsApp messages about voting for a young ballerina / scholarship, sent from compromised contacts (‘votare una giovane ballerina’, ‘borsa di studio’).
- [Web page content] Fake finalist information – two finalists, photos, vote counts, and a Prague dance school are shown on the fraudulent site (‘due finaliste’, ‘una scuola di danza di Praga’).